CVE-2024-12175: Rockwell Automation Code Execution Vulnerability in Arena
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12175?
CVE-2024-12175 is a critical vulnerability that could allow remote code execution due to a use after free condition.
How do I fix CVE-2024-12175?
To mitigate CVE-2024-12175, update Rockwell Automation Arena to version 16.20.07 or later.
What are the consequences of exploiting CVE-2024-12175?
Exploiting CVE-2024-12175 could allow a threat actor to execute arbitrary code within the context of the software.
Which versions of Rockwell Automation Arena are affected by CVE-2024-12175?
CVE-2024-12175 affects all versions of Rockwell Automation Arena prior to 16.20.07.
Is there a workaround for CVE-2024-12175 until a patch is available?
Currently, there are no official workarounds for CVE-2024-12175, and upgrading to a secure version is recommended.